Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Apache CXF — Vulnerabilities & Security Advisories 48

All 48 CVE vulnerabilities found in Apache CXF, with AI-generated Chinese analysis, references, and POCs.

This page catalogs vulnerability aggregations for the Apache CXF web services framework, focusing on common weakness enumeration tags associated with its architecture. It collects a comprehensive range of security defects identified in Apache CXF, including buffer overflows, injection flaws, and improper access control issues, covering data from the initial public release through recent critical patches. Readers can use this resource to track vendor advisories for Apache CXF, understand the historical context of specific weakness classes affecting JAX-WS implementations, and look up the product’s complete vulnerability history to assess risk exposure. By centralizing these records, the page provides a clear view of how security issues have evolved within the framework, helping developers and security professionals identify patterns in recurring defect types. This aggregation emphasizes the importance of keeping Apache CXF up to date, as many listed weaknesses remain relevant if older versions are still in use. The information presented is derived from official vendor notifications, independent security research, and widely recognized vulnerability databases. It serves as a reference point for auditing systems that rely on Apache CXF for interoperability between Java applications and web services. Users interested in the security posture of this middleware component will find detailed descriptions of each vulnerability, along with references to relevant patches or configuration mitigations. This resource does not provide real-time monitoring but offers a structured overview of past and present threats to aid in long-term security planning and remediation strategies for enterprise environments using this technology.

Vendor: Apache Software Foundation

CVE IDTitleCVSSSeverityPublished
CVE-2026-57818 Apache CXF: OAuth2 Authorization Code Replay via TOCTOU in JCacheCodeDataProvider CWE-367--2026-08-06
CVE-2026-61466 Apache CXF: OAuth2 Dynamic Client Registration Scope Self-Escalation CWE-304--2026-08-06
CVE-2026-63687 Apache CXF: JwtRequestCodeFilter silently overrides outer PKCE and nonce parameters CWE-345--2026-08-06
CVE-2026-65583 Apache CXF: Self-issued ID token claims validation skipped CWE-345--2026-08-06
CVE-2026-68079 Apache CXF: DefaultEncryptingCodeDataProvider allows unlimited authorization code replay CWE-294--2026-08-06
CVE-2026-68481 Apache CXF: Revocation bypass in DefaultEncryptingOAuthDataProvider CWE-672--2026-08-06
CVE-2026-65432 Apache CXF: XXE via WSDL/XSD import parsing CWE-611--2026-08-06
CVE-2026-57817 Apache CXF: The authorization code hash (c_hash) is not enforced for the hybrid OIDC flow CWE-20--2026-08-06
CVE-2026-66909 Apache CXF: Unsafe deserialization of inbound JMS ObjectMessage CWE-502--2026-08-06
CVE-2026-64958 Apache CXF: Denial of service via message header attachments CWE-400--2026-08-06
CVE-2026-57819 Apache CXF: No default restriction on the amount of form parameters per message CWE-400--2026-08-06
CVE-2026-54225 Apache CXF: Denial of Service attack via large attachments CWE-770--2026-08-06
CVE-2026-50645 Apache CXF: No restriction on attachment headers per message CWE-400--2026-06-12
CVE-2026-50634 Apache CXF: WS JSON request filter trusts metadata from an unvalidated first signature entry CWE-347--2026-06-12
CVE-2026-50633 Apache CXF: JNDI Injection vulnerability in DispatchMDBMessageListenerImpl CWE-20--2026-06-12
CVE-2026-50632 Apache CXF: JNDI Injection Vulnerability in JMSConfigFactory CWE-20--2026-06-12
CVE-2026-50631 Apache CXF: OAuth2: TOCTOU Race Condition in Refresh Token Processing CWE-367--2026-06-12
CVE-2026-50630 Apache CXF: OAuth2: HTTP Response Splitting via WWW-Authenticate Realm Injection CWE-113--2026-06-12
CVE-2026-50629 Apache CXF: OAuth2: Log Injection via Unsanitized Client Identifier CWE-93--2026-06-12
CVE-2026-50628 Apache CXF: OAuth2: Inverted IP Binding Check Defeats Security Control CWE-20--2026-06-12
CVE-2026-50627 Apache CXF: OAuth2: Missing JWT Audience and Issuer Validation in Access Token Validator CWE-289--2026-06-12
CVE-2026-49875 Apache CXF: XML External Entity (XXE) Injection in W3CMultiSchemaFactory and EndpointReferenceUtils CWE-611--2026-06-12
CVE-2026-50623 Apache CXF: Authentication Bypass in OAuth2 TokenIntrospectionService CWE-287--2026-06-12
CVE-2026-44417 Apache CXF: Incomplete fix for CVE-2025-48913 (Untrusted JMS configuration can lead to RCE) CWE-20--2026-05-22
CVE-2026-44618 Apache CXF: XXE vulnerability in WS-Transfer functionality CWE-611--2026-05-22
CVE-2026-44930 Apache CXF: LDAP Injection vulnerability in XKMS LDAP Repository CWE-90--2026-05-22
CVE-2025-48913 Apache CXF: Untrusted JMS configuration can lead to RCE CWE-20 9.8 -2025-08-08
CVE-2025-48795 Apache CXF: Denial of Service and sensitive data exposure in logs CWE-400 5.5 -2025-07-15
CVE-2025-23184 Apache CXF: Denial of Service vulnerability with temporary files CWE-400 5.9 Medium2025-01-21
CVE-2024-41172 Apache CXF: Unrestricted memory consumption in CXF HTTP clients CWE-401 7.5 -2024-07-19

All 48 known CVE vulnerabilities affecting Apache CXF with full Chinese analysis, references, and POCs where available.